Attackers abuse GitHub and Jira notification systems to deliver phishing emails
Attackers are routing malicious content through the legitimate infrastructure of trusted SaaS platforms, bypassing SPF, DKIM, and DMARC, the three...
Jira is a widely used project management and issue-tracking software developed by Atlassian. It helps teams plan, track, and manage their work efficiently. Created for software development teams, Jira has expanded its use to various industries and teams with different workflows.
Cloudwards says Jira is part of their “best project management software.”
Is Jira HIPAA compliant? Yes, based on our research, Jira is HIPAA compliant.
As of May 2026, our review did not identify any publicly disclosed changes to Jira HIPAA-related policies or BAA terms.
Yes, Jira will sign a business associate agreement through Atlassian, which can be reviewed here.
The Atlassian (Jira) BAA covers the use and disclosure of protected health information (PHI), stating, "This BAA is applicable only to the extent that Customer has an active Subscription Term for a HIPAA-Qualified Cloud Product and has configured such HIPAA-Qualified Cloud Product in accordance with the specifications provided in Section 5 of this BAA."
Their BAA covers:
Atlassian’s BAA outlines various limits and restrictions concerning the handling and disclosure of PHI according to the Health Insurance Portability and Accountability Act (HIPAA) and its regulations. These include:
Jira signs a BAA and is therefore HIPAA compliant.
Learn more: HIPAA Compliant Email: The Definitive Guide
A business associate agreement (BAA) is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of personal health information (PHI) as required by HIPAA regulations.
The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the privacy and security of certain health information, known as protected health information (PHI).
HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
Attackers are routing malicious content through the legitimate infrastructure of trusted SaaS platforms, bypassing SPF, DKIM, and DMARC, the three...
Confluence has been around since 2004, created as an enterprise-grade "knowledge management system," similar to a wiki. It's one of many software...
Atlassian, which provides a number of popular software development tools like Jira, Confluence, and Trello, has announced changes to its server and...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.